Privacy
Choose guest storage or an explicit hosted workspace
EstateLedger keeps guest records in this browser. Optional email/password accounts store one validated workspace per account in a Cloudflare D1 database only when you choose Upload to cloud.
Guest mode
Guest workspaces stay in browser storage. The app keeps a recovery copy when it finds malformed saved data. Export a backup before clearing browser data or changing devices.
Hosted accounts
An account stores your name, email, password hash, session records, and one workspace containing estate details, tasks, and ledger entries. Workspace responses are private and uncacheable. Every hosted read and write is checked against the authenticated account; another account cannot address your workspace.
Your controls
- Upload to cloud is an explicit action; signing in never uploads an existing guest workspace automatically.
- Reload cloud copy is an explicit replacement of the current local view; export first if you have local changes.
- Sign out switches to the guest namespace and does not reuse the previous account's local cache.
- Delete account removes the hosted account and its hosted workspace. Exported backups remain on your device and are not deleted by the server.
Residual account prerequisite
Email verification and password recovery are not enabled because a transactional mail provider is not configured for this deployment. EstateLedger does not pretend to send those messages. Use a strong unique password and keep an exported backup.
Scope
EstateLedger does not sell estate records, use them for advertising, or provide bank-import processing. This product is organizational software, not legal advice.